RBAC Roles for Console Connect (Completed)

We have been testing console connect and it is great. However, we have circumstances where our cyber defense team will not want certain groups to have all of the functionality available. 

For example, our service desk is outsourced. Cyber defense would not want them to have the ability to remotely modify command line, powershell or file transfer. 

Is this planned in the future?

1

Comments (5 comments)

0
Avatar
Jens Nygaard

I'm also wondering why the “help desk” role cant use the “connect” 

 

0
Avatar
Chris Leon
(Edited )

When trying to add Console Connect and User Sessions as a custom role, one gets replaced with the other. 
Please add it so you can have both roles, or at the very least let Console Connect include User Sessions. 

As others stated, we do not want to give full access to helpdesk. 

0
Avatar
Marcus Cassidy

We would like this too. Console connect should be part of each RBAC role from Helpdesk upwards. We would like to use Console Connect as our primary support tool for AVD relating issues/screensharing as it's more convenient than Teams.

0
Avatar
Chris Leon

Just got a tip from Qaadir, to create a custom role and just use the Manage Sessions permission, that gives them access to only sessions/console connect. 

0
Avatar
Chad Manzer

Thank you for the feedback I'm glad to hear that Console Connect has been working well for you.

You’ve raised a great point regarding permission controls, especially in more locked down environments. We are currently working on expanding Toolbox functionality, and following that, one of my next goals is to introduce more granular permissions for Console Connect.
Specifically, I am planning to separate access into two distinct RBAC roles (role names not final):

  1. Screenshare-only – limited to the currently logged-in users permissions with no elevated access.
  2. Full Toolbox Access – which would include command line, PowerShell, file transfer, and other admin-level tools to run against the user's session/host/desktop.

I wanted to make sure you know this is on our roadmap, and while I can’t provide a specific timeline just yet, I’ve tagged this thread internally and will follow up here as we get closer to releasing additional Console Connect RBAC roles. 

Thanks again for your input!!

Side note on the helpdesk role not providing Console Connect access there was some internal complexities how we handle RBAC assignments, which caused some issues, and it is being fixed.  
 

Please sign in to leave a comment.